<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ldap authentication via ssh in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/3357168#M247559</link>
    <description>&lt;P&gt;How do you set it to PAP only?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2018 03:07:00 GMT</pubDate>
    <dc:creator>autoko1@3</dc:creator>
    <dc:date>2018-03-29T03:07:00Z</dc:date>
    <item>
      <title>Ldap authentication via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659323#M247489</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just bought a cisco 1921 and i'm trying to identify my users against an LDAP server. I have two problems:&lt;/P&gt;&lt;P&gt;-When I use the test command to test the authentication (test aaa group ...), it only works when the password is in cleartext in the LDAP server.&lt;/P&gt;&lt;P&gt;-When I try to login via ssh to the router, I got this error in my syslog:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1465: *Jul 22 11:18:49.255: AAA/BIND(0000002D): Bind i/f&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1466: *Jul 22 11:18:49.255: AAA/AUTHEN/LOGIN (0000002D): Pick method list 'LDAP_login'&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1467: *Jul 22 11:18:49.255: LDAP: LDAP: Queuing AAA request 45 for processing&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1468: *Jul 22 11:18:49.255: LDAP: Received queue event, new AAA request&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1469: *Jul 22 11:18:49.255: LDAP: LDAP authentication request&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1470: *Jul 22 11:18:49.255: LDAP: Username/Password sanity check failed!!&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-bottom: 0.0001pt; margin-right: 0cm; margin-left: 0cm; font-size: 12pt; font-family: 'Times New Roman', serif;"&gt;Jul 22 13:18:24 10.20.42.3 1471: *Jul 22 11:18:49.255: LDAP: LDAP doesn't suport interactive login&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any solution? Or is it just for VPN login?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659323#M247489</guid>
      <dc:creator>lafourchette</dc:creator>
      <dc:date>2019-03-11T01:14:41Z</dc:date>
    </item>
    <item>
      <title>Ldap authentication via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659324#M247494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 08:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659324#M247494</guid>
      <dc:creator>lafourchette</dc:creator>
      <dc:date>2011-07-27T08:30:19Z</dc:date>
    </item>
    <item>
      <title>Ldap authentication via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659325#M247513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really? Nobody ever tried to authenticate via LDAP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 09:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659325#M247513</guid>
      <dc:creator>lafourchette</dc:creator>
      <dc:date>2011-08-22T09:38:46Z</dc:date>
    </item>
    <item>
      <title>Ldap authentication via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659326#M247530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have agonised over this my self.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems ldap can only authenticate using PAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set your client to PAP only and it works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this, using chap:&lt;/P&gt;&lt;P&gt;*Oct 27 11:33:27.875: LDAP: LDAP authentication request&lt;/P&gt;&lt;P&gt;*Oct 27 11:33:27.875: LDAP: Username/Password sanity check failed!!&lt;/P&gt;&lt;P&gt;*Oct 27 11:33:27.875: LDAP: Notifying AAA: REQUEST FAILED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then using PAP:&lt;/P&gt;&lt;P&gt;*Oct 27 11:35:06.987: LDAP: LDAP Messages to be processed: 1&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: LDAP Message type: 97&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Got ldap transaction context from reqid 47ldap_parse_result&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: resultCode:&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Success)&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Received Bind Responseldap_parse_result&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Ldap Result Msg: SUCCESS, Result code =0&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: LDAP Bind successful for DN:CN=***********,CN=******,DC=****,DC=com&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: * LDAP PASSWORD VERIFY DONE *&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Next Task: All authentication task completed&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Transaction context removed from list [ldap reqid=47]&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: * * AUTHENTICATION COMPLETED SUCCESSFULLY * *&lt;BR /&gt;*Oct 27 11:35:06.987: LDAP: Notifying AAA: REQUEST SUCCESSldap_msgfree&lt;BR /&gt;ldap_result&lt;BR /&gt;wait4msg (timeout 0 sec, 1 usec)&lt;BR /&gt;ldap_select_fd_wait (select)&lt;BR /&gt;ldap_err2string&lt;/P&gt;&lt;P&gt;*Oct 27 11:35:06.987: LDAP: Finished processing ldap msg, Result:Success&lt;BR /&gt;*Oct 27 11:35:06.995: %IP_VFR-7-FEATURE_DISABLE_IN: VFR(in) is manually disabled through CLI; VFR support for features that have internally enabled, will be made available only when VFR is enabled manually on interface Virtual-Access3&lt;BR /&gt;*Oct 27 11:35:06.999: LDAP: Received socket event&lt;BR /&gt;*Oct 27 11:35:07.007: %LINK-3-UPDOWN: Interface Virtual-Access3, changed state to up&lt;BR /&gt;*Oct 27 11:35:07.011: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access3, changed state to up &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 11:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/1659326#M247530</guid>
      <dc:creator>Andrew Norman</dc:creator>
      <dc:date>2011-10-27T11:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Ldap authentication via ssh</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/3357168#M247559</link>
      <description>&lt;P&gt;How do you set it to PAP only?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 03:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-authentication-via-ssh/m-p/3357168#M247559</guid>
      <dc:creator>autoko1@3</dc:creator>
      <dc:date>2018-03-29T03:07:00Z</dc:date>
    </item>
  </channel>
</rss>

